CVE-2018-16889
published 2019-01-28CVE-2018-16889: Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via…
PriorityP337high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
0.54%
41.7th percentile
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ceph | < ceph 12.2.11+dfsg1-1 (bookworm) | ceph 12.2.11+dfsg1-1 (bookworm) |
| redhat | ceph | <= 13.2.4 | — |
| redhat | ceph | >= 0 < 10.2.11-0ubuntu0.16.04.2 | 10.2.11-0ubuntu0.16.04.2 |
| the_ceph_project | ceph | — | — |
| the_ceph_project | ceph | >= 0 < 12.2.11+dfsg1-1 | 12.2.11+dfsg1-1 |
| the_ceph_project | ceph | >= 0 < 12.2.11+dfsg1-1 | 12.2.11+dfsg1-1 |
| the_ceph_project | ceph | >= 0 < 12.2.11+dfsg1-1 | 12.2.11+dfsg1-1 |
| the_ceph_project | ceph | >= 0 < 12.2.11+dfsg1-1 | 12.2.11+dfsg1-1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_ubuntu5.7MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ceph vulnerabilities
vendor_ubuntu·2019-06-25·CVSS 5.7
CVE-2018-14662 [MEDIUM] Ceph vulnerabilities
Title: Ceph vulnerabilities
Summary: Several security issues were fixed in Ceph.
It was discovered that Ceph incorrectly handled read only permissions. An
authenticated attacker could use this issue to obtain dm-crypt encryption
keys. This issue only affected Ubuntu 16.04 LTS. (CVE-2018-14662)
It was discovered that Ceph incorrectly handled certain OMAPs holding
bucket indices. An authenticated attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 16.04 LTS.
(CVE-2018-16846)
It was discovered that Ceph incorrectly sanitized certain debug logs. A
local attacker could possibly use this issue to obtain encryption key
information. This issue was only addressed in Ubuntu 18.10 and Ubuntu
19.04. (CVE-2018-16889)
It was discovered that Ceph inco
Red Hat
ceph: debug logging for v4 auth does not sanitize encryption keys
vendor_redhat·2019-01-10·CVSS 5.5
CVE-2018-16889 [MEDIUM] CWE-538 ceph: debug logging for v4 auth does not sanitize encryption keys
ceph: debug logging for v4 auth does not sanitize encryption keys
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.
It was found that Ceph RGW did not properly sanitize encryption keys in debug logging for v4 auth. Encryption keys could be inadvertently disclosed when sharing debug logs.
Package: ceph (Red Hat Ceph Storage 2) - Not affected
Package: ceph-common (Red Hat Enterprise Linux 7) - Not affected
Package: ceph (Red Hat Enterprise Linux 8) - Not affected
Package: redhat-virtualization-host (Red Hat Virtualization 4) - Not affected
Debian
CVE-2018-16889: ceph - Ceph does not properly sanitize encryption keys in debug logging for v4 auth. Th...
vendor_debian·2018·CVSS 5.5
CVE-2018-16889 [MEDIUM] CVE-2018-16889: ceph - Ceph does not properly sanitize encryption keys in debug logging for v4 auth. Th...
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.
Scope: local
bookworm: resolved (fixed in 12.2.11+dfsg1-1)
bullseye: resolved (fixed in 12.2.11+dfsg1-1)
forky: resolved (fixed in 12.2.11+dfsg1-1)
sid: resolved (fixed in 12.2.11+dfsg1-1)
trixie: resolved (fixed in 12.2.11+dfsg1-1)
GHSA
GHSA-2xfm-mgc4-j8fx: Ceph does not properly sanitize encryption keys in debug logging for v4 auth
ghsa_unreviewed·2022-05-13
CVE-2018-16889 [HIGH] CWE-200 GHSA-2xfm-mgc4-j8fx: Ceph does not properly sanitize encryption keys in debug logging for v4 auth
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.
OSV
ceph vulnerabilities
osv·2019-06-25·CVSS 5.7
CVE-2018-14662 [MEDIUM] ceph vulnerabilities
ceph vulnerabilities
It was discovered that Ceph incorrectly handled read only permissions. An
authenticated attacker could use this issue to obtain dm-crypt encryption
keys. This issue only affected Ubuntu 16.04 LTS. (CVE-2018-14662)
It was discovered that Ceph incorrectly handled certain OMAPs holding
bucket indices. An authenticated attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 16.04 LTS.
(CVE-2018-16846)
It was discovered that Ceph incorrectly sanitized certain debug logs. A
local attacker could possibly use this issue to obtain encryption key
information. This issue was only addressed in Ubuntu 18.10 and Ubuntu
19.04. (CVE-2018-16889)
It was discovered that Ceph incorrectly handled certain civetweb requests.
A remote attacker
OSV
CVE-2018-16889: Ceph does not properly sanitize encryption keys in debug logging for v4 auth
osv·2019-01-28·CVSS 7.5
CVE-2018-16889 [HIGH] CVE-2018-16889: Ceph does not properly sanitize encryption keys in debug logging for v4 auth
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-16889 ceph: debug logging for v4 auth does not sanitize encryption keys [fedora-all]
bugzilla·2019-01-11·CVSS 5.5
CVE-2018-16889 [MEDIUM] CVE-2018-16889 ceph: debug logging for v4 auth does not sanitize encryption keys [fedora-all]
CVE-2018-16889 ceph: debug logging for v4 auth does not sanitize encryption keys [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2018-16889 ceph: debug logging for v4 auth does not sanitize encryption keys
bugzilla·2019-01-11·CVSS 5.5
CVE-2018-16889 [MEDIUM] CVE-2018-16889 ceph: debug logging for v4 auth does not sanitize encryption keys
CVE-2018-16889 ceph: debug logging for v4 auth does not sanitize encryption keys
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext.
Upstream Patch:
https://github.com/ceph/ceph/pull/25881/commits
Upstream Bug:
http://tracker.ceph.com/issues/37847
Discussion:
Created ceph tracking bugs for this issue:
Affects: fedora-all [bug 1665335]
---
This issue has been addressed in the following products:
Red Hat Ceph Storage 3.3
Via RHSA-2019:2538 https://access.redhat.com/errata/RHSA-2019:2538
---
This issue has been addressed in the following products:
Red Hat Ceph Storage 3 for Red Hat Enterprise Linux 7
Via RHSA-2019:2541 https://access.redhat.com/errata/RHSA-2019:254
http://www.securityfocus.com/bid/106528https://access.redhat.com/errata/RHSA-2019:2538https://access.redhat.com/errata/RHSA-2019:2541https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16889https://usn.ubuntu.com/4035-1/http://www.securityfocus.com/bid/106528https://access.redhat.com/errata/RHSA-2019:2538https://access.redhat.com/errata/RHSA-2019:2541https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16889https://usn.ubuntu.com/4035-1/
2019-01-28
Published